Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory

Tycoon2FA

Also known astycoon2fa

Tycoon2FA is a phishing-as-a-service (PhaaS/PaaS) platform active since 2023 that uses adversary-in-the-middle (AiTM/AitM) techniques to bypass multi-factor authentication by capturing credentials and session cookies during live authentication sessions. It is described as a subscription-based toolkit sold through Telegram for about $120 and has been identified by Microsoft as the most active phishing platform of the year. The platform targets cloud accounts, especially Microsoft 365 and other cloud services, and has been used in large-scale credential harvesting and phishing campaigns. Observed Tycoon2FA tradecraft includes fake CAPTCHA pages, obfuscated JavaScript used to proxy victim credentials to legitimate Microsoft 365 login pages, theft of session cookies after CAPTCHA validation, and automated logins into victims’ Microsoft Entra ID accounts after capturing credentials and MFA tokens. Campaigns have also used anti-bot pages with obfuscated JavaScript, anti-debugger timing checks, browser fingerprinting, URL shorteners, links embedded in legitimate presentation platforms, compromised SharePoint environments, and trusted redirect chains. One reported campaign impersonated a law firm and used a newly spoofed domain to deliver a settlement-agreement signature lure. The content also states that Tycoon2FA now deploys device code flow phishing, indicating expansion beyond its established AiTM phishing capability. In these campaigns, it has targeted cloud environments and Microsoft 365 access through device code phishing lures. Microsoft and Europol disrupted Tycoon2FA in March 2026 in an international operation that seized 330 domains used for phishing pages and control infrastructure. The disruption contributed to a temporary decline in attacks, but reporting indicates the operators rapidly rebuilt infrastructure and resumed operations within days, with activity returning to near prior levels. Post-disruption reporting says the group shifted infrastructure away from earlier hosting patterns and increasingly used second-level domains and .RU domains. No sub-groups are identified in the provided content, and no aliases beyond Tycoon2FA are directly mentioned.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

12 of 15 tactics30 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1598
Phishing for Information
TA0042
Resource Development
1 technique
T1584
Compromise Infrastructure
T1584.006
Web Services
TA0001
Initial Access
3 techniques
T1078×2
Valid Accounts
T1199
Trusted Relationship
T1566×4
Phishing
T1566.001
Spearphishing Attachment
T1566.002×2
Spearphishing Link
T1566.003
Spearphishing via Service
TA0002
Execution
1 technique
T1204
User Execution
TA0003
Persistence
1 technique
T1078×2
Valid Accounts
TA0004
Privilege Escalation
1 technique
T1078×2
Valid Accounts
TA0005
Stealth
5 techniques
T1027
Obfuscated Files or Information
T1036
Masquerading
T1078×2
Valid Accounts
T1497
Virtualization/Sandbox Evasion
T1622
Debugger Evasion
TA0006
Credential Access
6 techniques
T1111
Multi-Factor Authentication Interception
T1528
Steal Application Access Token
T1539×4
Steal Web Session Cookie
T1557×5
Adversary-in-the-Middle
T1621
Multi-Factor Authentication Request Generation
T1649
Steal or Forge Authentication Certificates
TA0007
Discovery
2 techniques
T1497
Virtualization/Sandbox Evasion
T1622
Debugger Evasion
TA0008
Lateral Movement
1 technique
T1534
Internal Spearphishing
TA0009
Collection
2 techniques
T1114
Email Collection
T1114.003
Email Forwarding Rule
T1557×5
Adversary-in-the-Middle
TA0011
Command and Control
1 technique
T1104
Multi-Stage Channels
ACTIVITY FEED

Recent activity

7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

levelblueNews
Jun 9, 2026
The Device Code Phishing Tsunami: What We’re Seeing in the Wild

Established AiTM phishing platform targeting Microsoft 365 that has expanded to device code flow phishing, using anti-bot protections, obfuscated anti-analysis JavaScript, browser fingerprinting, and spoofed legal/document-signature lures.

Read more
techradarNews
May 1, 2026
QR code phishing surges 146% as Microsoft detects and analyzes 8.3 billion phishing threats in Q1 2026 - attackers are changing tactics to bypass security | TechRadar

Phishing-as-a-service group associated with credential phishing campaigns. After a joint disruption by Microsoft and Europol, the group’s activity dropped temporarily but it began rehosting infrastructure, with many domains shifting to .RU TLDs.

Read more
scworldNews
May 1, 2026
Microsoft: QR code, CAPTCHA-gated phishing more than double in Q1 2026 | news | SC Media

A phishing-as-a-service platform associated with high-volume credential phishing campaigns using CAPTCHA-gated phishing pages. Following disruption in early March 2026, it partially recovered and shifted infrastructure away from Cloudflare-hosted services to new top-level domains, with many domains moving to .ru.

Read more
cyber security newsNews
Mar 24, 2026
Tycoon2FA Operators Resume Cloud Account Phishing After Infrastructure Disruption

Operators behind the Tycoon2FA phishing-as-a-service platform resumed large-scale cloud account phishing after a law enforcement takedown, using adversary-in-the-middle phishing to bypass MFA and compromise Microsoft 365 and other cloud accounts.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping22

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.